Skip to main content

Internal Network Visibility

You cannot secure what you cannot see — and for most organizations the least-visible part of the estate is the internal network. Assets appear and disappear as teams stand up servers, connect devices, and deploy internal services, often without central tracking. Internal Network Visibility gives you a continuously updated inventory of what actually exists behind the firewall, so it can be assessed and governed like everything else.

What it does

  • Discovers internal assets. Identifies hosts, services, and internal applications reachable inside your network segments — including systems that no cloud console or external scanner will ever list.
  • Builds a living inventory. Discovered internal assets join the same Asset Inventory as your cloud resources, so you have one catalog spanning cloud and on-prem instead of two.
  • Surfaces open services and exposure. Enumerates listening services and ports on internal hosts, highlighting unexpected exposure inside the perimeter (lateral-movement risk, forgotten services, shadow IT).
  • Feeds downstream assessment. Once an internal asset is known, it becomes a target for OpenVAS vulnerability scanning and private URL/API scanning, and a subject for Wazuh endpoint monitoring.

Why it matters

  • Internal is where lateral movement happens. Once an attacker has a foothold, the internal network is their playground. Visibility into internal services and their weaknesses is what limits blast radius.
  • Shadow IT and drift. Internal environments change constantly. Continuous discovery catches the database someone spun up "temporarily" and the service that was supposed to be decommissioned.
  • Audit scope accuracy. Auditors ask what's in scope. A complete, current internal inventory answers that question with data instead of guesswork.

How it fits the unified picture

Internal assets are first-class citizens in the platform. A vulnerability found on an internal host is triaged in the same Vulnerability Management queue as a cloud misconfiguration, promoted into the same Risk Register, and counted toward the same compliance controls. There is no separate "internal" dashboard to reconcile.

Network reachability

Internal discovery and scanning run from within your network so they can reach private segments. Which segments are in scope, and how the scanner is positioned, is part of deployment planning handled during onboarding.